Live data from Hacker News

Adding a security key to Gmail

techsolidarity.org

121–126 of 126 posts

Re: Adding a security key to Gmail

#121
post #35

How does the communication between the USB key and Google in a browser work? Will it work on all operating systems and browsers?

As for the operating systems: in order to use it on your phone, you'll need to be careful to use a YubiKey with NFC support and have a phone that supports NFC. You won't have any trouble using it on Windows/Ubuntu/macOS. As for the browsers: Chrome/Chromium works fine. Firefox has an addon that adds security key support[0]. Unfortunately, this addon has a bug which causes high CPU load[1]. Firefox is also working on…

U2F itself as a browser API is a dead-end and will be replaced with newer FIDO 2 WebAuthentication API, but fear not - it's supposed to be compatible with U2F tokens in use [0].

WebAuthentication will be supported in all major modern browsers [1], it just takes some time to implement.

[0]: https://bugzilla.mozilla.org/show_bug.cgi?id=1065729#c254

[1]: https://www.chromestatus.com/feature/5669923372138496

Re: Adding a security key to Gmail

#123
post #6

The article mentions Yubikey at $18. As an alternative, the Nitrokey U2F is only €9 (€11 including delivery) https://shop.nitrokey.com/shop/product/nitrokey-u2f-5

Yubikey U2F is much higher quality physically than Nitrokey U2F. I wouldn't trust the nitrokey to last very long. I may be wrong, but that's just the impression from comparing them in my hands

Re: Adding a security key to Gmail

#124
post #100
post #95

Earlier quoted context omitted.

I guess I didn't understnd that bit. It sounds like there is som mistunderstanding about how Yubico authenticator works? It does not store the secrets on the disk/memory of the phone/laptop at all. It just sends over a code. The device only sees one code and nothing else. This is also why a user can get a new phone and and just tap the key to the new phone and truck on. Magic. When a user drops their Google Authentic…

No, I understand that. Let me simplify my point: Whether or not the TOTP secret is on the smartphone, encrypted or not, or sent to it from another device, is the wrong attack vector to optimize for. Getting mainstream users en masse to consistently and correctly use any 2fa is a win. Furthermore, you're moving the goalposts a bit by using the Yubikey in this scenario. So sure, if someone compromises your phone they d…

Getting mainstream users to use 2FA? Is that like getting them not to use overly simple PWs? Or not use open wifi? Those people?make Not sound like an ahole but...How's that working out for ya?

I think ya might be able to argue that if you're going to add friction (e.g., Yubikey) you're also creating a great senses of seriousness. That sense of seriousness is seriously lacking.

All that said, the UN + PW idea is too weak. We need something that's up to the threat AND is also appropriate to the risk of loss. Best I can tell, as a general mainstream rule, we're not even close to that. It's 2017? Really?

Re: Adding a security key to Gmail

#126
post #107
post #104

Earlier quoted context omitted.

Cookie theft is for sure a real issue. In the case of Google, if your cookie suddenly pops up in another country, it will often be quickly terminated. Not all services do this, and Google does no do it all the time either. Still, I see no reason not to take the super easy low-hanging fruit to reduce attack surface when you can.

They may of compromised gmail, because gmail is logged in. They however won't get to the other 20 services that I have not recently logged into recently on the device that also use hardware tokens. They don't get the totp secret for my AWS account which I only log into from that device in emrgencies. Etc. If someone gets remote access to your device it is a very bad day, but you -can- have damage control and a clear…

And then there is the recent story of someone getting private emails/password resets/paypal info sent because Gmail ignores the dot in their email address... https://news.ycombinator.com/item?id=14140569 - which makes one wonder if that's already an attack angle being used.
Post reply on HN